Bugs item #1672291, was opened at 2007-03-02 10:55
Message generated for change (Comment added) made by fgo_gl
You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=100235&aid=1672291&group_id=235

Please note that this message will contain a full copy of the comment thread,
including the initial issue submission, for this request,
not just the latest update.
Category: None
Group: 2.0.0 beta 5
Status: Open
Resolution: None
>Priority: 5
Private: No
Submitted By: Fabian (fgo_gl)
Assigned to: Nobody/Anonymous (nobody)
Summary: ICQ password broken after changing it (pw > 8 chars)

Initial Comment:
Hi,

unfortunately I have to report a serious bug in Gaim. When changing your ICQ 
password and your desired new password is longer than eight chars, it will 
become unusable. You won't be able to login with your new password!

I could reproduce this bug with another created account after I've locked 
myself out... I've tried to capture the packet with the password change 
request, but up to now I wasn't able to convert it back to plain text 
information.

In Bug 487645 there might be additional information. One thing for sure: ICQ 
passwords may just be 8 characters long. Gaim should handle that...

Best regards,
Fabian.

----------------------------------------------------------------------

>Comment By: Fabian (fgo_gl)
Date: 2007-03-02 12:33

Message:
Logged In: YES 
user_id=1630077
Originator: YES

Hi,

after trying to debug with gdb I got some new information:
If the password is longer than eight characters, you can use the first
eight characters for logging in. The whole password string will be sent to
the ICQ server, but only the length passwdlen in aim_icq_changepasswd() -->
aimbs_putle16(&fr->data, passwdlen+1); will be interepreted. 

I think the best solution for this problem would be limiting the input
field for the new passwords to 8 characters when they are used in an ICQish
context.

It seems I did enter garbage for my new password, so my old account is
lost...:( But really strange about that is, that the same thing happened
with another account I created for getting to know how my password was
corrupted and with a third account everything is working fine... Any
ideas?

Best regards,
Fabian.

----------------------------------------------------------------------

You can respond by visiting: 
https://sourceforge.net/tracker/?func=detail&atid=100235&aid=1672291&group_id=235

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys-and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Gaim-bugs mailing list
Gaim-bugs@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/gaim-bugs

Reply via email to